Automation & Ops ✓ Google · Official google-secopsdetection-engineeringthreat-intelligencesynthetic-udm-eventsyara-lrule-coveragemcp

Google SecOps Detection Coverage Evaluator

Trace threat intelligence through coverage testing and reviewed rule creation in Google SecOps.

FollowSkills review · FSRS-2.0
Not recommended
46/ 100 5-point scale 2.3 / 5
Trust13 / 25 · 2.6/5

The skill requires user approval before creating rules and describes the flow from blog text through TDOs and synthetic UDM events to SecOps deployment. It does not define least-privilege permissions, sensitive-threat-data handling, credential isolation, deployment rollback, or rule removal/reversal, so points are deducted.

Reliability7 / 20 · 1.8/5

The sequence, full TDO/UDM loops, and tool calls are reasonably explicit. However, SecOps MCP dependencies are assumed, and input validation, exception branches, retries, partial-failure recovery, and diagnosable error handling are missing. With static review and no test evidence, the score is capped below 10.

Adaptability9 / 15 · 3.0/5

The intended audience and scenarios are fairly clear, and threat hunting and SOC investigative actions are explicitly excluded. Trigger boundaries, prerequisites, MCP availability, mainland-China network reachability, Chinese-language support, and behavior for malformed or unsuitable blog content are not specified.

Convention9 / 15 · 3.0/5

The documentation includes metadata, staged workflow instructions, an output schema, tool references, and repository-level installation guidance. The repository also supplies an Apache-2.0 license, contribution guidance, support path, and an active-development note. The skill lacks its own versioning, changelog, explicit maintainer/update path, dependency setup, examples, and troubleshooting guidance.

Effectiveness5 / 15 · 1.7/5

The workflow covers intelligence extraction, TDO generation, synthetic events, coverage evaluation, rule generation, and approval-gated deployment, so the core value proposition is plausible. Correctness, tool behavior, generated-rule quality, and comparative benefit over manual work lack file-contained execution evidence; outputs still require review, so the static score is capped at 7.

Verifiability3 / 10 · 1.5/5

The files provide auditable workflow steps, tool names, parameter constraints, and an output structure. There is no committed test suite, CI coverage, fixed fixture, or third-party execution evidence, leaving limited corroboration of key claims.

Evidence confidence:Low Reviewed Jul 20, 2026 Reviewed revision 513a7a51e85f
The upstream repository has new commits since this review. The score still applies to the reviewed revision shown and may not cover the latest changes.
Before you use it
  • Creating rules changes the external SecOps environment; obtain per-rule confirmation and verify the target project, permission scope, and rollback procedure before execution.
  • Do not send unsanitized threat intelligence, UDM data, or rule content to unreviewed external services; the skill does not specify retention, access control, or sensitive-field handling.
  • Confirm that the required SecOps MCP tools, credentials, and regional network access are available, and define manual handling for tool failures, empty results, and invalid JSON.
Review evidence [1][2][3][4]
See the full review method →

What does this skill do, and when should you use it?

This skill supports an end-to-end detection engineering workflow for Google SecOps. It extracts threat intelligence from a blog URL, generates Threat Detection Opportunities, and creates synthetic UDM events for each opportunity. It then evaluates existing rule coverage, checks whether matching rules are enabled and alerting, and generates YARA-L 2.0 rules for gaps. Creating new rules requires user approval and a configured SecOps MCP server.

Extracts the complete blog text from a supplied URL; calls Google SecOps MCP tools to generate Threat Detection Opportunities; generates synthetic UDM events for every TDO; evaluates each event against existing rules; checks the enabled and alerting_enabled status of matched rules; generates YARA-L 2.0 rules for coverage gaps; produces a structured summary of TDOs, coverage, gaps, and errors; and, after approval, calls create_rule to add approved rules.

  1. A security engineer wants to identify detectable attacker behaviors from a threat-intelligence blog.
  2. A SecOps team needs to validate existing detection coverage with synthetic UDM events.
  3. A detection engineer needs to verify whether matched rules are enabled and configured for alerting.
  4. A security team has coverage gaps and wants YARA-L 2.0 rules generated for the relevant TDOs.
  5. A SecOps administrator wants to create reviewed rules in Google SecOps after per-rule approval.

What are this skill's strengths and limitations?

Pros
  • Covers the workflow from threat-intelligence extraction through reviewed rule creation.
  • Explicitly processes every TDO and every generated synthetic UDM event.
  • Checks both rule enablement and alerting status.
  • Keeps human control over rule creation through approval.
Limitations
  • Requires Google SecOps MCP tools and a configured SecOps MCP server.
  • Rule creation is gated by user approval rather than being automatic.
  • The source provides no test-suite, performance, or cross-platform validation evidence.
  • It is explicitly out of scope for threat hunting and SOC investigations.

How do you install this skill?

Run npx skills add google/skills, then select the SecOps Detection Coverage Skill from the repository during installation. The source does not document a specific installation directory or additional runtime setup.

How do you use this skill?

In an environment with a configured Google SecOps MCP server, provide a threat-intelligence blog URL and request a coverage evaluation. Example: "Evaluate Google SecOps detection coverage for this blog URL, generate rules for gaps, and ask for my approval before creating each rule." Do not use this skill for threat hunting or SOC investigative actions.

FAQ

Does the source specify a cost?
No. The source does not specify the skill's cost or the pricing of Google SecOps MCP tools.
Can it create rules without permission?
No. The workflow requires user approval and supports approving or rejecting each generated rule individually.
What access or connection is required?
A configured Google SecOps MCP server is required; the source does not provide more detailed permission requirements.
Can it be used for investigations or threat hunting?
No. The description explicitly excludes threat hunting and SOC investigative actions.

More skills from this repository

All from google/skills

Automation & Ops ✓ Google · Official

Google Cloud Storage Basics

Manage GCS buckets and objects while configuring access, protection, lifecycle, cost, and performance.

Data & Analysis ✓ Google · Official

Google Cloud Data Lineage Summary

Summarize BigQuery and GCS lineage to debug data quality and provenance.

Data & Analysis ✓ Google · Official

AlloyDB Database Manager

Manage AlloyDB clusters, instances, and backups with CLI, IaC, client-library, and MCP guidance.

Dev & Engineering ✓ Google · Official

Gemini Enterprise Managed Agents

Manage stateful Gemini Enterprise agents through the Managed Agents API.

Dev & Engineering ✓ Google · Official

Google Ads MCP Setup Guide

A practical guide to installing and connecting the read-only Google Ads MCP server.

Automation & Ops ✓ Google · Official

Google Cloud Monitoring Metric Finder

Discover and filter relevant monitoring metrics for GCP services.

Data & Analysis ✓ Google · Official

BigQuery Asset Impact Analysis

Map the downstream blast radius of BigQuery table or view changes.

Automation & Ops ✓ Google · Official

Google Cloud Reliability Architect

Evaluate and improve Google Cloud workload reliability using the Well-Architected Framework.

Dev & Engineering ✓ Google · Official

Google Analytics Admin API Assistant

Automate Google Analytics account, property, and data-stream configuration.

Automation & Ops ✓ Google · Official

Google Cloud Authentication Guide

Choose secure Google Cloud authentication and authorization for local, production, and cross-cloud workloads.

Automation & Ops ✓ Google · Official

Google Cloud Solution Architect

Plan, validate, and package end-to-end architectures for complex multi-product Google Cloud workloads.

Automation & Ops ✓ Google · Official

Google Cloud Workload Manager Evaluator

Evaluate Google Cloud workloads against best-practice rules and review actionable findings.

Dev & Engineering ✓ Google · Official

Google Bigtable Basics

Design, configure, query, and troubleshoot Google Bigtable workloads.

Automation & Ops ✓ Google · Official

Google Cloud Live Multimodal Streaming Architect

Design and deploy Google Cloud solutions for live, bidirectional multimodal streams.

Dev & Engineering ✓ Google · Official

Google Data Manager API Audience Import Assistant

Guides developers through reliable, diagnosable audience-member uploads to Google Ads or DV360.

Automation & Ops ✓ Google · Official

GKE Production Golden Path

Set production-oriented GKE defaults, readiness checks, and decision guardrails for cluster design.

Automation & Ops ✓ Google · Official

Google Cloud WAF Security Advisor

Assesses Google Cloud workloads against Well-Architected security principles and produces actionable improvement guidance.

Data & Analysis ✓ Google · Official

Google Ads Account Diagnostics

Find the causes of conversion loss, low lead flow, and lost ad opportunities.

Automation & Ops ✓ Google · Official

Google Cloud AI Agent Builder

Design, implement, deploy, and validate AI agents and multi-agent systems on Google Cloud.

Automation & Ops ✓ Google · Official

GKE Enterprise RAG Search Architect

Designs and validates enterprise RAG search systems built on GKE and AlloyDB.

Related skills